Aggregator
New ClickFix Attack Imitates Ministry of Defence Website to Target Windows & Linux Systems
A newly identified cyberattack campaign has surfaced, leveraging the recognizable branding of India’s Ministry of Defence to distribute cross-platform malware targeting both Windows and Linux systems. Uncovered by threat intelligence researchers at Hunt.io, this operation employs a ClickFix-style infection chain, mimicking official government press release portals to lure unsuspecting users into executing malicious payloads. The […]
The post New ClickFix Attack Imitates Ministry of Defence Website to Target Windows & Linux Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
UK’s NCSC Offers Security Tips as Co-op Confirms Data Loss
CVE-2020-1805 | Huawei Honor V10 prior 10.0.0.156(C00E156R2P4) Driver Parameter out-of-bounds (sa-20200422-02)
CVE-2020-1806 | Huawei Honor V10 prior 10.0.0.156(C00E156R2P4) Driver Parameter out-of-bounds (sa-20200422-02)
CVE-2020-1880 | Huawei Lion-AL00C prior 10.0.0.205(C00E202R7P2) input validation (sa-20200415-02)
CVE-2020-9489 | Tika OneNote Parser memory leak
CVE-2020-10944 | Hashicorp Nomad/Nomad Enterprise up to 0.10.4 Web UI cross site scripting (Issue 7468)
CVE-2020-1774 | OTRS up to 5.0.42/6.0.27/7.0.16 Certificates Download insertion of sensitive information into sent data (DLA 2198-1)
CVE-2020-11014 | Electron Cash SLP Edition up to 3.6.1 Mint Tool privileges management
CVE-2020-12261 | Open-AudIT 3.3.0 cross site scripting (ID 157401 / EDB-48516)
Threat Actor Evades SentinelOne EDR to Deploy Babuk Ransomware
Aon’s Stroz Friedberg Incident Response Services has uncovered a method used by a threat actor to bypass SentinelOne Endpoint Detection and Response (EDR) protections, ultimately deploying a variant of the notorious Babuk ransomware. SentinelOne EDR, a widely-used endpoint protection solution, is designed to detect and block threats with robust anti-tamper mechanisms that prevent unauthorized disabling […]
The post Threat Actor Evades SentinelOne EDR to Deploy Babuk Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Samsung MagicINFO 9 Server Vulnerability Actively Exploited in the Wild
A critical security vulnerability in the Samsung MagicINFO 9 Server has come under active exploit, security researchers from Arctic Wolf have warned. The flaw, tracked as CVE-2024-7399, allows unauthenticated attackers to remotely execute code and compromise digital signage infrastructure in organizations around the world. Details of the Vulnerability The Samsung MagicINFO 9 Server is a popular […]
The post Samsung MagicINFO 9 Server Vulnerability Actively Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.